Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Isn't that a really, really juicy target though?


LetsEncrypt doesn't see your private key when you obtain the certificate. So no, it's not _really_ a juicy target.


On the other hand, who's gong to notice a LE issued cert that they did not request in the certificate transparency logs?


The ones who monitor their domains in the CT log.

(Mom-and-pop-stores probably won’t. Other orgs might.)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: